Key Takeaways

  • EasyEquities, Cell C and Bidvest Bank disclosed potential breaches linked to third-party services during the same weekend.
  • Available evidence suggests the incidents may relate to a Dire Wolf ransomware attack on one South African-founded business.
  • The disclosures highlight concentration risk in identity verification, compliance and customer-service supply chains.

EasyEquities, Cell C and Bidvest Bank have alerted customers to potential data exposure after cybersecurity incidents affecting third-party services connected to their operations. The closely timed notifications, issued over the same weekend, suggest the three cases share a common or closely related service dependency rather than representing separate compromises of each company's core infrastructure.

Available information also indicates that the incidents may be connected to a Dire Wolf ransomware attack on a single South African-founded business. That link remains an emerging part of the investigation, so the precise scope, affected systems and path between the attack and each customer notification have yet to be fully established.

Cell C told fibre customers that credentials used to access a third-party environment supporting its fibre business had been compromised. The potentially exposed information included customer names, email addresses, mobile numbers and account numbers. Cell C said its investigation was continuing and described the incident as confined to the third-party environment.

EasyEquities reported a similar pattern. The investment platform notified clients that a third party used for regulatory verification checks had experienced a cybersecurity incident. EasyEquities said its internal checks found no compromise of EasyEquities or Purple Group systems, and no evidence that customer account security had been breached.

Bidvest Bank also informed customers that a third party holding limited categories of customer information had been affected. Taken together, the disclosures point toward the sort of supplier concentration that can remain largely invisible until something goes wrong. One service can sit behind onboarding, regulatory checks or customer administration for several prominent brands.

Data involved in verification processes can remain useful to criminals even when passwords, payment credentials and account access are unaffected. Names, contact details and account identifiers may support convincing phishing messages, impersonation attempts or social-engineering calls. Customers could receive communications that look credible precisely because they contain accurate personal details.

SABRIC reported R2.4 billion in South African digital banking crime losses across 110,074 incidents in 2025. Banking apps accounted for 88.6% of cases and 70.5% of the value lost. The newly disclosed incidents do not establish that fraud occurred, but exposed identity and account data can feed the manipulation techniques used in digital banking crime.

The Check Point Financial Threat Landscape 2025 recorded 1,858 cyber incidents affecting financial institutions in 2025, up from 864 in 2024, while data breaches increased 73%. Connectivity providers face similar attention from attackers, particularly where customer records, billing systems and access credentials intersect.

Modern onboarding and compliance processes often depend on tightly integrated external services. Identity and know-your-customer vendors such as TransUnion, Experian and GBG illustrate how deeply verification capabilities can be embedded in financial workflows, although the available disclosures do not identify any of those companies as involved in this event.

Conventional supplier questionnaires and annual compliance reviews provide only a snapshot of risk. The NIST Cybersecurity Supply Chain Risk Management guidance encourages organizations to treat supplier exposure as an ongoing governance issue. Practical controls include mapping where customer data travels, limiting retained fields, separating vendor credentials, monitoring third-party access and testing how quickly a compromised connection can be disabled.

POPIA obligations place attention on how South African organizations and their operators protect personal information and communicate potential exposure. For EasyEquities, Cell C and Bidvest Bank, the immediate task is incident containment and customer communication. Outsourced verification may reduce operational friction, but shared dependencies can turn one ransomware event into a cross-sector security problem.